Mexico CNBV allows SMS bank authentication
CNBV’s rule change takes effect Sept. 2, 2026 and allows SMS as an authentication factor for banks in Mexico.
CNBV has amended the rules on electronic banking operations and set Sept. 2, 2026, as the effective date for a change that allows SMS as an authentication factor for certain banking transactions. The move comes amid Banxico warnings about fraud using its image, new bank alerts, and tighter KYC and cybersecurity demands on the financial sector.
CNBV has amended Articles 319 Bis 2, 319 Bis 3, and 319 Bis 5 of the rules applicable to credit institutions on electronic operations, and set a single transitional provision that puts the new rules on the sending of authentication factors and SMS use into force on Sept. 2, 2026. The change applies to banking in Mexico and requires adjustments to digital transaction verification schemes.
What changes with the CNBV reform?
The resolution authorizes the sending of security codes by SMS to authenticate certain banking transactions, according to CNBV and Expansión’s coverage, while preserving stronger schemes for higher-risk operations. Revista Flow added that the goal is to make digital banking easier to use without loosening controls where risk is higher.
That regulatory shift was also summarized by Zero Trust Consulting as an expansion of the banking authentication channel, with effects on user experience and on the risk models of institutions that rely on mobile apps and remote agents. The CNBV notice in the Diario Oficial de la Federación also sets the exact implementation date, Sept. 2, 2026.
What other obligations do financial institutions face?
Institutions must not only adapt their authentication factors, they also face ongoing customer identification and verification requirements under the LFPIORPI, according to Truora, which describes a KYC standard that applies before, during, and not only at the start of the customer relationship.
At the same time, companies focused on financial services say that complying with CNBV cybersecurity and data protection frameworks requires immutable evidence of information protection and operational continuity, in line with technical controls such as ISO 27001, according to E-dea. Scram2k’s case involving a Mexican financial group illustrates that regulatory pressure: after a CNBV audit found 47 critical vulnerabilities left unremediated, the entity implemented a 24/7 SOC, added a Fortinet-based vulnerability management platform, and fixed the issues in 90 days, while also automating regulatory reports.
How did the financial system react to fraud risk?
Banco de México said on Sept. 5, 2026 that it never asks for personal or financial information by phone calls, text messages, email, or social media, and reiterated prevention measures against fraud attempts that use its image. Expansión later reported that Banamex also reminded customers that it will not ask them to install apps through links sent by SMS or suspicious emails.
Those warnings sit alongside the authentication reform and a broader financial digitization agenda. Ámbito said the Digital CURP is emerging as a trust mechanism for remotely proving identity and that CNBV, together with the Finance Ministry and Banco de México, would have specific roles in regulating and operating payments and financial services within that framework. Pagoralia also said that N2 Bis accounts will be able to receive monthly deposits of up to 15,000 UDIS, with a maximum of 3,000 UDIS in cash, pushing the rest of the funds toward CNBV-supervised digital channels.
Sources
- Grupo financiero: 47 vulnerabilidades remediadas y SOC operativo en 30 díasscram2k.com· Scram2k
- Claudia Sheinbaum avanza en eliminar el dinero en efectivo en México: así es la reforma de economía digital con la nueva CURP como punto claveambito.com· Ámbito
- El Banco de México advierte sobre intentos de fraude que usan su nombrex.com· Banco de México
- Resolución por la que se reforman los artículos 319 Bis 2, 319 Bis 3 y 319 Bis 5 de las Disposiciones de carácter general aplicables a las instituciones de crédito en materia de operaciones por medios electrónicosdof.gob.mx· Comisión Nacional Bancaria y de Valores (CNBV)Unverified URL
- Relanzamiento de Banxico y nuevos pagos digitales en 2026pagoralia.com· Pagoralia
- El nuevo estándar de KYC para el ecosistema fintech en LATAMblog.truora.com· Truora
- Gobernanza de ciberseguridad e ISO 27001 en la regióne-dea.co· E-dea
- Autenticación bancaria archivos | Revista Flowrevistaflow.com· Revista Flow
- ZTC Cyber Intelligence 003 | 7 de septiembre de 2026zerotrust.consulting· Zero Trust Consulting
- Bancos aumentan alertas antifraude; Banamex pide a clientes no instalar apps desde enlaces sospechososexpansion.mx· Expansión



